Zero-config mesh VPN for secure private network access using WireGuard.
Technical Overview & Architecture
Tailscale is a zero-configuration mesh VPN that creates an encrypted private network (tailnet) between your devices, servers, containers, and cloud infrastructure using WireGuard as the underlying transport protocol. Founded in 2019 by ex-Google engineers, Tailscale eliminates the complexity of traditional VPN setup (certificate management, gateway servers, routing table configuration) by handling device authentication via OAuth (Google, Microsoft, GitHub), automatic NAT traversal, and peer-to-peer key exchange. Every device on a Tailscale network gets a stable 100.x.x.x IP address that remains consistent regardless of the device's real IP or location. This enables engineers to securely access development servers, internal dashboards, staging databases, and self-hosted tools from any network — at home, in a coffee shop, or at a customer site — without exposing ports to the public internet. Tailscale ACLs (access control lists) use a JSON policy file that defines which devices and users can communicate with which other devices and services, replacing complex firewall rules with a readable declarative access policy. Subnet routing and exit nodes extend the tailnet to existing VPC CIDR ranges and provide full internet traffic routing through trusted servers.
Pricing Breakdown
Transparent tiers and feature allotments for engineering teams.
Personal (Free)
- 3 users
- 100 devices
- All WireGuard features
- MagicDNS
- Community support
Starter
- 5 users
- 100 devices
- ACL policies
- Subnet routing
- Priority support
Premium
- Unlimited users
- SSO (Okta/Azure AD)
- SCIM provisioning
- Custom OIDC
- Audit logs
- Priority support
Enterprise
- Dedicated support
- Custom contracts
- Compliance documentation
- SLA
Compare Tailscale Against Alternatives
See how Tailscale stacks up against competitor tools across speed, APIs, and pricing.